CVE-2025-24886 - Pwn College CTFd Symlink LFI

CVE ID : CVE-2025-24886 Published : Jan. 30, 2025, 11:15 p.m. | 1 hour, 59 minutes ago Description : pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a user clones or updates repositories, a check is performed to see if the repository had contained any symlinks. A malicious user could craft a repository with symlinks pointed to sensitive files and then retrieve them using the CTFd website. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Jan 31, 2025 - 02:16
 0  0
CVE-2025-24886 - Pwn College CTFd Symlink LFI
CVE ID : CVE-2025-24886
Published : Jan. 30, 2025, 11:15 p.m. | 1 hour, 59 minutes ago
Description : pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a user clones or updates repositories, a check is performed to see if the repository had contained any symlinks. A malicious user could craft a repository with symlinks pointed to sensitive files and then retrieve them using the CTFd website.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...